Jann Horn
b70eb420e9
bpf: Fix tnum constraints for 32-bit comparisons
...
[ Upstream commit 604dca5e3af1db98bd123b7bfc02b017af99e3a0 ]
The BPF verifier tried to track values based on 32-bit comparisons by
(ab)using the tnum state via 581738a681b6 ("bpf: Provide better register
bounds after jmp32 instructions"). The idea is that after a check like
this:
if ((u32)r0 > 3)
exit
We can't meaningfully constrain the arithmetic-range-based tracking, but
we can update the tnum state to (value=0,mask=0xffff'ffff'0000'0003).
However, the implementation from 581738a681b6 didn't compute the tnum
constraint based on the fixed operand, but instead derives it from the
arithmetic-range-based tracking. This means that after the following
sequence of operations:
if (r0 >= 0x1'0000'0001)
exit
if ((u32)r0 > 7)
exit
The verifier assumed that the lower half of r0 is in the range (0, 0)
and apply the tnum constraint (value=0,mask=0xffff'ffff'0000'0000) thus
causing the overall tnum to be (value=0,mask=0x1'0000'0000), which was
incorrect. Provide a fixed implementation.
Fixes: 581738a681b6 ("bpf: Provide better register bounds after jmp32 instructions")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200330160324.15259-3-daniel@iogearbox.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
2020-04-17 10:50:25 +02:00
..
bpf
bpf: Fix tnum constraints for 32-bit comparisons
2020-04-17 10:50:25 +02:00
cgroup
cgroup1: don't call release_agent when it is ""
2020-04-01 11:01:51 +02:00
configs
debug
kgdb: don't use a notifier to enter kgdb at panic; call directly
2019-09-25 17:51:40 -07:00
dma
dma-mapping: Fix dma_pgprot() for unencrypted coherent pages
2020-04-17 10:50:01 +02:00
events
perf/core: Fix mlock accounting in perf_mmap()
2020-02-11 04:35:54 -08:00
gcov
Revert "um: Enable CONFIG_CONSTRUCTORS"
2020-02-01 09:34:53 +00:00
irq
genirq/debugfs: Add missing sanity checks to interrupt injection
2020-04-17 10:50:11 +02:00
livepatch
locking
locking/lockdep: Avoid recursion in lockdep_count_{for,back}ward_deps()
2020-04-17 10:50:05 +02:00
power
ACPI: PM: s2idle: Avoid possible race related to the EC GPE
2020-02-19 19:52:56 +01:00
printk
printk: fix exclusive_console replaying
2020-02-24 08:36:24 +01:00
rcu
rcu: Allow only one expedited GP to run concurrently with wakeups
2020-03-05 16:43:50 +01:00
sched
sched/core: Remove duplicate assignment in sched_tick_remote()
2020-04-17 10:50:17 +02:00
time
time/sched_clock: Expire timer in hardirq context
2020-04-17 10:50:02 +02:00
trace
ftrace/kprobe: Show the maxactive number on kprobe_events
2020-04-17 10:50:21 +02:00
.gitignore
acct.c
async.c
audit.c
audit: always check the netlink payload length in audit_receive_msg()
2020-03-05 16:43:42 +01:00
audit.h
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit_get_nd(): don't unlock parent too early
2019-11-10 11:56:55 -05:00
auditfilter.c
audit: fix error handling in audit_data_to_entry()
2020-03-05 16:43:42 +01:00
auditsc.c
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Ignore pm_wakeup_pending() for disable_nonboot_cpus()
2020-04-17 10:50:11 +02:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
keys: Fix request_key() cache
2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
elfcore.c
kernel/elfcore.c: include proper prototypes
2019-09-25 17:51:39 -07:00
exec_domain.c
exit.c
exit: panic before exit_mm() on global init exit
2020-01-09 10:20:01 +01:00
extable.c
fail_function.c
fork.c
mm: fork: fix kernel_stack memcg stats for various stack implementations
2020-04-01 11:02:03 +02:00
freezer.c
Revert "libata, freezer: avoid block device removal while system is frozen"
2019-10-06 09:11:37 -06:00
futex.c
futex: Unbreak futex hashing
2020-03-25 08:25:58 +01:00
gen_kheaders.sh
kheaders: substituting --sort in archive creation
2019-10-17 09:08:19 +09:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
jump_label: Don't warn on __exit jump entries
2019-08-29 15:10:10 +01:00
kallsyms.c
kallsyms: Don't let kallsyms_lookup_size_offset() fail on retrieving the first symbol
2019-08-27 16:19:56 +01:00
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: bail out upon SIGKILL when allocating memory.
2019-09-25 17:51:40 -07:00
kexec_elf.c
kexec_elf: support 32 bit ELF files
2019-09-06 23:58:44 +02:00
kexec_file.c
Merge branch 'next-lockdown' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
2019-09-28 08:14:15 -07:00
kexec_internal.h
kheaders.c
kmod.c
kmod: make request_module() return an error when autoloading is disabled
2020-04-17 10:50:22 +02:00
kprobes.c
kprobes: Fix optimize_kprobe()/unoptimize_kprobe() cancellation logic
2020-03-12 13:00:09 +01:00
ksysfs.c
kthread.c
kthread: make __kthread_queue_delayed_work static
2019-10-16 09:20:58 -07:00
latencytop.c
Makefile
Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity
2019-09-27 19:37:27 -07:00
module-internal.h
module.c
module: avoid setting info->name early in case we can fall back to info->mod->name
2020-02-24 08:36:54 +01:00
module_signature.c
module_signing.c
notifier.c
x86/mm: split vmalloc_sync_all()
2020-03-25 08:25:58 +01:00
nsproxy.c
padata.c
padata: always acquire cpu_hotplug_lock before pinst->lock
2020-04-08 09:08:47 +02:00
panic.c
panic: ensure preemption is disabled during panic()
2019-10-07 15:47:19 -07:00
params.c
pid.c
pid_namespace.c
profile.c
ptrace.c
ptrace: reintroduce usage of subjective credentials in ptrace_has_cap()
2020-01-23 08:22:36 +01:00
range.c
reboot.c
relay.c
resource.c
mm/memory_hotplug.c: use PFN_UP / PFN_DOWN in walk_system_ram_range()
2019-09-24 15:54:09 -07:00
rseq.c
seccomp.c
seccomp: Add missing compat_ioctl for notify
2020-04-17 10:50:09 +02:00
signal.c
signal: Extend exec_id to 64bits
2020-04-17 10:50:12 +02:00
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stacktrace: Don't skip first entry on noncurrent tasks
2019-11-04 21:19:25 +01:00
stop_machine.c
stop_machine: Avoid potential race behaviour
2019-10-17 12:47:12 +02:00
sys.c
Merge branch 'timers-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2019-09-17 12:35:15 -07:00
sys_ni.c
sysctl.c
kernel: sysctl: make drop_caches write-only
2020-01-04 19:18:32 +01:00
sysctl_binary.c
task_work.c
taskstats.c
taskstats: fix data-race
2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
up.c
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog/softlockup: Enforce that timestamp is valid on boot
2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c
workqueue: don't use wq_select_unbound_cpu() for bound works
2020-03-18 07:17:50 +01:00
workqueue_internal.h